PCI DSS 4.0, requirement by requirement.

All 12 requirements and 351 controls of version 4.0.1, with evidence attached where the assessor will look for it.

4.0 raised the bar

PCI DSS 4.0 is not a refresh. It added customised implementation, tightened authentication, expanded logging and scripting requirements, and pushed a set of previously best-practice items into mandatory status.

If you handle cardholder data, the requirement applies whether you are filling in a self-assessment questionnaire or engaging a QSA for a Report on Compliance. Either way you are evidencing 12 requirements across hundreds of sub-requirements, annually.

OpenGRC includes the full PCI DSS 4.0.1 bundle — 351 controls including the Appendix A requirements for shared hosting and service providers — on every plan.

Built for annual validation

Evidence where the assessor looks.

Scoped to your environment

Scoped to your environment

Applicability is set per control, so the requirements that do not apply to your cardholder data environment are recorded as such with a reason, rather than quietly ignored.

Evidence attached to sub-requirements

Evidence attached to sub-requirements

PCI assessment is granular. Each control carries its implementation, test procedure and evidence, so when an assessor asks about 8.3.6 the answer and its proof are in the same place.

A portal for your QSA

A portal for your QSA

Your assessor gets an MFA-protected panel with time-bounded, revocable access, IP allow-listing and immutable versioned submissions — and you get a record of everything they opened.

The 12 requirements

RequirementControls
1 Network security controls24
2 Secure configurations14
3 Protect stored account data36
4 Protect data in transit8
5 Anti-malware17
6 Secure systems and software24
7 Restrict access by business need15
8 Identify users and authenticate35
9 Restrict physical access32
10 Log and monitor34
11 Test security regularly27
12 Policies and programmes47
A1 / A3 Multi-tenant and designated entities34

PCI DSS questions

Which version is included?

PCI DSS 4.0.1, the current revision, with 351 controls covering all 12 requirements plus the Appendix A requirements for multi-tenant service providers and designated entities.

Does OpenGRC complete our SAQ or RoC?

Can it track scope?

We also carry SOC 2 and ISO 27001.